Meta and Google Apps Send Over 26,000 Data Points Daily, Oxford Study Finds

A recent study has exposed the extraordinary volume of personal information collected by mobile applications from Meta and Google, painting a picture of data practices that extend far beyond what many users might expect. Researchers at the University of Oxford examined more than 30 popular apps across both Android and iOS platforms, tracking exactly what kinds of information these programs send back to their parent companies during ordinary use. The findings, published through academic channels and covered by The Register, reveal that these applications transmit hundreds of distinct data points every hour, often without clear signals to the people holding the phones.

The scale of collection stands out immediately. Meta-owned apps, including Facebook, Instagram, and WhatsApp, together accounted for more than 14,000 distinct data transmissions during a controlled testing period that simulated typical daily activity. Google applications such as YouTube, Google Maps, and the core Google app followed closely behind with over 12,000 transmissions. These numbers represent not simple logins or basic analytics but detailed behavioral signals ranging from device identifiers and location coordinates to inferred interests, social connections, and even subtle patterns in how users scroll or pause while viewing content.

What makes these transmissions particularly striking is their frequency and persistence. The Oxford team discovered that many apps continue sending data even when the phone is locked or the application appears to be closed. Background processes maintain connections that report sensor readings, network changes, and application usage patterns at regular intervals. On Android devices, where system-level permissions sometimes grant broader access, the volume of shared information reached peaks of nearly 500 distinct data points per hour for certain Meta products. iOS implementations showed slightly lower but still substantial numbers, suggesting that platform-specific privacy controls have only partially limited the flow.

Location data emerges as one of the most frequently harvested categories. Both companies’ applications request and receive precise geographic coordinates multiple times per session, often combining this with timestamps, device orientation, and movement vectors to build detailed profiles of daily routines. The study found that mapping and navigation apps from Google naturally lead in this area, but social platforms from Meta are not far behind. Instagram, for instance, regularly transmits location alongside information about nearby WiFi networks and Bluetooth beacons, allowing the company to refine its understanding of where users spend time even when they have not explicitly checked in.

Advertising identifiers play a central role in this data economy. Both platforms generate unique advertising IDs that persist across applications and can be refreshed or reset by users. The research showed these identifiers being bundled with almost every transmission, creating long-term threads that connect activity across different apps and websites. Even when users attempt to limit tracking through system settings, the study observed workarounds that rely on other stable device signals such as hardware fingerprints, screen resolution combined with installed font lists, and detailed battery statistics.

The types of information being gathered extend into more personal territory than many realize. App usage patterns reveal which other programs users open, how long they spend in each one, and even which features within those programs receive the most attention. For Meta properties, this includes granular interaction data from Instagram Reels, such as which videos users watch completely, which they skip after a few seconds, and which they rewatch multiple times. These signals feed directly into recommendation algorithms that shape future content displays. Google applications similarly monitor search queries, video playback behavior on YouTube, and navigation patterns in Maps, using these inputs to refine both advertising targeting and product features.

Device information forms another major category. The researchers documented transmissions containing details about operating system versions, installed applications, storage capacity, processor type, and even current battery temperature. While some of this data supports technical functions like crash reporting, much of it also contributes to profiling systems that attempt to identify users across different devices or detect when someone switches to a new phone. The persistence of these signals raises questions about how effectively users can separate their online identities even when they take steps like clearing caches or using private browsing modes.

The study methodology involved installing fresh copies of the applications on test devices, granting all requested permissions, and then performing standardized sequences of actions that mirrored common user behaviors. These included scrolling through feeds, watching videos, searching for content, and switching between applications. Network traffic was captured and analyzed to identify every distinct piece of information being sent to company servers. The team categorized these transmissions according to their apparent purpose, separating functional data from tracking data where possible, though the line between the two often proved blurry.

One notable finding involves the role of software development kits provided by both companies. Many third-party applications incorporate Meta or Google libraries that automatically transmit data back to the original providers even when the user never directly interacts with a Meta or Google product. This creates invisible data pipelines that extend the reach of these corporations across vast portions of the mobile app universe. The Oxford researchers estimated that these indirect collection channels multiply the effective scope of data gathering well beyond what users see in their app lists.

Both Meta and Google have responded to previous criticism by emphasizing user controls and transparency features. Meta points to its off-Facebook activity tool and privacy checkup prompts, while Google highlights its privacy dashboard and auto-delete options for location history and web activity. The study authors acknowledge these tools exist but question their effectiveness given the sheer volume of data still being collected. Many users remain unaware of how much information continues to flow despite adjusting settings, partly because the interfaces for managing these preferences are complex and buried within multiple menu layers.

The financial implications of this data collection are substantial. Meta reported advertising revenue exceeding $150 billion in its most recent full year, almost entirely dependent on its ability to target users with precision. Google similarly generates the majority of its income through advertising systems that rely on the detailed profiles built from mobile data. This creates powerful incentives to maximize collection while maintaining plausible claims about user consent and privacy protection. Regulators in Europe and elsewhere have imposed fines and demanded changes, yet the fundamental business models remain built around extensive personal data.

Privacy advocates have long argued that current consent mechanisms fail to provide genuine choice. When installing popular applications, users face lengthy terms of service that few read in full, and the practical costs of refusing permissions often include reduced functionality or complete inability to use the app. The Oxford study adds concrete evidence to these arguments by quantifying exactly how much data moves even under standard usage conditions that most people would consider normal.

Technical experts note that some data transmission serves legitimate purposes. Applications need to communicate with servers to deliver content, verify accounts, and maintain security. The challenge lies in distinguishing necessary technical data from expansive behavioral profiling. The study found numerous examples where information appeared to serve both purposes simultaneously, making meaningful oversight difficult even for sophisticated analysts.

Looking at specific applications provides additional insight. Facebook’s main app transmitted data related to social graph information, including details about friends, groups, and pages that users interact with. Instagram focused heavily on visual content consumption patterns and shopping-related signals. WhatsApp, despite its end-to-end encryption for messages, still sends substantial metadata about who users communicate with and when. On the Google side, the core search app collects query data alongside contextual information about the user’s location and recent activity. YouTube tracks viewing habits with remarkable granularity, including pause points and volume adjustments that might indicate levels of engagement.

The research also examined what happens when users take steps to protect their privacy. When advertising identifiers were reset and tracking limitations enabled, the volume of data decreased but did not disappear. Alternative identifiers and behavioral fingerprints continued to flow, suggesting that complete disconnection from these data networks requires more drastic measures such as using alternative operating systems or avoiding the applications entirely.

These findings arrive at a time when public awareness of data practices has grown but regulatory responses remain uneven. The European Union’s Digital Markets Act and various state-level laws in the United States attempt to impose new restrictions, yet enforcement faces significant technical and legal hurdles. Companies can argue that much of the data supports personalization that users claim to want, while critics counter that the systems create addictive feedback loops and enable manipulative advertising.

For ordinary users, the study serves as a reminder that mobile phones function as sophisticated tracking devices as much as communication tools. Every tap, scroll, and location check potentially contributes to detailed profiles that companies use for purposes ranging from ad targeting to product development. While complete avoidance of these platforms may not be realistic for many people, understanding the scope of collection can inform decisions about which applications to use, which permissions to grant, and when to employ privacy-enhancing tools like VPNs or alternative browsers.

The Oxford researchers plan to expand their analysis to additional applications and to examine how data practices evolve over time as companies respond to regulatory pressure and technical changes. Their work adds to a growing body of evidence suggesting that mobile data collection has reached levels that would have seemed implausible just a decade ago. As smartphones become even more integrated into daily life, the question of how much visibility into personal behavior should be considered acceptable continues to gain urgency.

Both Meta and Google maintain that their practices comply with applicable laws and that users benefit from more relevant experiences as a result of the data they provide. The companies have introduced various transparency reports and have made commitments to limit certain types of sensitive data collection. Whether these measures will meaningfully reduce the volume documented in the study remains to be seen. For now, the research stands as a detailed accounting of information flows that operate largely outside the direct view of the people generating the data with every interaction. The patterns revealed suggest that mobile applications from these two organizations function as highly efficient data gathering instruments, capturing signals across multiple dimensions of human behavior and device usage with remarkable consistency and depth.


Discover more from Web and IT News

Subscribe to get the latest posts sent to your email.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top

Discover more from Web and IT News

Subscribe now to keep reading and get access to the full archive.

Continue reading